Changes for page Password Security and Hygiene
Last modified by Chase Eckert on 2026/08/19 16:32
From version 22.1
edited by steve@remc1_org
on 2021/02/25 05:09
on 2021/02/25 05:09
Change comment:
There is no comment for this version
To version 34.1
edited by Lauren Keller
on 2021/08/17 13:00
on 2021/08/17 13:00
Change comment:
There is no comment for this version
Summary
-
Page properties (3 modified, 0 added, 0 removed)
-
Objects (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Title
-
... ... @@ -1,1 +1,1 @@ 1 -Password Security 1 +Password Security and Hygiene - Author
-
... ... @@ -1,1 +1,1 @@ 1 -XWiki. steve@remc1_org1 +XWiki.lkeller@remc1_org - Content
-
... ... @@ -1,5 +3,3 @@ 1 -=== === 2 - 3 3 {{toc/}} 4 4 5 5 === {{id name="Good-Passwords-Are-Hard-To-Find"/}}Good Passwords Are Hard To Find === ... ... @@ -8,13 +8,13 @@ 8 8 9 9 === {{id name="How-Do-I-Choose-A-Good-Password?"/}}How Do I Choose A Good Password? === 10 10 11 -Arguably, the best advice comes from someone that understands how passwords are cracked; [[both are explained here>>url:https://www.schneier.com/essays/archives/2008/11/passwords_are_not_br.html||shape="rect"]]. Once you havea password,youcan check how strong it is: [[this one works through your browser>>url:https://random-ize.com/how-long-to-hack-pass/||shape="rect"]] so youdon'tneedtoupload your sensitive information anywhere. Ifit's good, use it and remember to change it ([[it's not as bad as it sounds>>url:https://blog.lastpass.com/2018/08/often-change-password.html/||shape="rect"]]).9 +Arguably, the best advice comes from someone that understands how passwords are cracked; [[both are explained here>>url:https://www.schneier.com/essays/archives/2008/11/passwords_are_not_br.html||shape="rect"]]. Come up with a passphrase; once you have something you'll remember, make another that is //similar// and check how strong the //similar password// is (never put your password anywhere except when using or saving it to a password manager): [[this one works through your browser>>url:https://random-ize.com/how-long-to-hack-pass/||shape="rect"]] so you won't be uploading your sensitive information anywhere, but it is still a good idea to test one that is different from your real password. If the similar password is as strong as you want it to be, use the one it mimicked, and remember to change it on occasion ([[it's not as bad as it sounds>>url:https://blog.lastpass.com/2018/08/often-change-password.html/||shape="rect"]]). 12 12 13 13 === {{id name="Compromised-Accounts-And-Passwords"/}}Compromised Accounts And Passwords === 14 14 15 15 We hear about high-profile breaches; if you are affected by one of these, the parties responsible for keeping your information safe will eventually contact you and let you know what you can do about it. 16 16 17 -But [[it has been reported>>url:https://arstechnica.com/information-technology/2019/01/hacked-and-dumped-online-773-million-records-with-plaintext-passwords/||shape="rect"]] that [[nearly a Billion compromised email accounts>>url:https://www.forbes.com/sites/kateoflahertyuk/2019/01/17/collection-1-breach-how-to-find-out-if-your-password-has-been-stolen/#28c21b512a2e||shape="rect"]] are published online. If you wonder whether yours is among them, head to [[';~~-~~-have i been pwned?>>url:https://haveibeenpwned.com/||shape="rect"]] and enter an email address. If you find yours, change your password for every account that uses that email address or password. You can also check whether [[one of your passwords has been compromised>>url:https://haveibeenpwned.com/Passwords||shape="rect"]] and sign up for notifications in the event a future breach or 'sensitive' data dump exposes your information. 15 +But [[it has been reported>>url:https://arstechnica.com/information-technology/2019/01/hacked-and-dumped-online-773-million-records-with-plaintext-passwords/||shape="rect"]] that [[nearly a Billion compromised email accounts>>url:https://www.forbes.com/sites/kateoflahertyuk/2019/01/17/collection-1-breach-how-to-find-out-if-your-password-has-been-stolen/#28c21b512a2e||shape="rect"]] are published online. If you wonder whether yours is among them, head to [[';~~-~~-have i been pwned?>>url:https://haveibeenpwned.com/||shape="rect"]] and enter an email address. If you find yours, change your password for every account that uses that email address or password. You can also check whether [[one of your passwords has been compromised>>url:https://haveibeenpwned.com/Passwords||shape="rect"]] and sign up for notifications in the event of a future breach or 'sensitive' data dump exposes your information. 18 18 19 19 [[image:attach:check_your_accounts.jpg||height="250"]] 20 20 ... ... @@ -26,20 +26,24 @@ 26 26 27 27 Our brains can only hold so much. [[In this survey>>url:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3515440/||shape="rect"]], 72% of the 263 participants had difficulty remembering their passwords. The result, as we already know, is we reuse and write down passwords. There are techniques for remembering passwords, but we can [[expect to need even more passwords>>url:https://techxplore.com/news/2018-12-passwords-ready.html||shape="rect"]] in the coming years. 28 28 29 -REMC1 is always looking at security; you've probably heard us mention 2- factorauthentication and passwordmanagers. Reputable password managers are availablefor your phoneas well as yourcomputer. If you alreadyuse [[LastPass>>url:http://lastpass.com||shape="rect"]] – which we recommended– they offer [[away to verifypasswordstrength>>url:https://support.logmeininc.com/lastpass/help/use-the-security-challenge-lp030011||shape="rect"]] andsee if your data has been compromised.27 +REMC1 is always looking at security; you've probably heard us mention 2-step verification (aka 2-factor authentication) and password managers. 30 30 29 +=== {{id name="Password-Managers"/}}Password Managers === 30 + 31 +Reputable password managers are available for your phone as well as your computer. [[Bitwarden>>url:https://bitwarden.com/||shape="rect"]] is free and [[promises to always be free>>url:https://proprivacy.com/password-manager/review/bitwarden#:~~:text=Bitwarden%20is%20free%20and%20open,for%20a%20premium%20personal%20account.||shape="rect"]]. 32 + 33 +[[LastPass>>url:http://lastpass.com||shape="rect"]] offers [[a way to verify password strength>>url:https://support.logmeininc.com/lastpass/help/use-the-security-challenge-lp030011||shape="rect"]], however recent changes allow you to use it for free only on either mobile devices or desktop machines, not both. 34 + 31 31 [[image:attach:password_managers.jpg||height="250"]] 32 32 33 33 \\ 34 34 35 -=== {{id name="2-Step-Verification-(2-factor- or-multi-factor-authentication)"/}}2-Step Verification (2factorormulti-factor authentication) ===39 +=== {{id name="2-Step-Verification-(2-factor-/-multi-factor-authentication)"/}}2-Step Verification (2-factor / multi-factor authentication) === 36 36 37 37 This feature provides an additional layer of security in case your password is compromised. REMC1 highly recommends that staff, especially administrative and administrative assistant staff, utilize this feature for their Google Account. Learn more about this at the [[Google Account Help Section on Setting up 2-Step Verification>>url:https://support.google.com/accounts/answer/185839?hl=en&ref_topic=7189195||shape="rect"]], our [[wiki page>>url:https://confluence.remc1.net/display/PS/Configuring+2-step%282-factor%29+authentication+for+Google||shape="rect"]], or viewing our [[video tutorial>>url:https://mistreamnet.eduvision.tv/Share.aspx?q=CT1wecDsedCLqkXQGflKaw%253d%253d||shape="rect"]]. 38 38 39 39 === {{id name="Questions?"/}}Questions? === 40 40 41 -REMC1 is always looking at security and you've probably heard us mention 2-factor authentication and password managers. 42 - 43 43 REMC staff is happy to answer any questions you have on potential spoofing, viruses, malware, and security. 44 44 45 45 \\
- Confluence.Code.ConfluencePageClass[0]
-
- id
-
... ... @@ -1,1 +1,1 @@ 1 -1718 95451 +17186260 - title
-
... ... @@ -1,1 +1,1 @@ 1 -Password Security 1 +Password Security and Hygiene